Junglewise Threat Intelligence

CVE-2026-73951: Oracle WebCenter Portal authentication bypass in Portlet Services

CVE-2026-73951 · Severity: high · CVSS 8.1 · Published 2026-09-15

Executive brief

Oracle WebCenter Portal is a collaboration platform that allows organizations to build portal applications. An unauthenticated remote vulnerability in the Portlet Services component allows attackers to completely compromise the portal, potentially gaining unauthorized access to sensitive business data and operational capabilities without any credentials.

Technical details

The vulnerability is a difficult-to-exploit authentication bypass or remote code execution flaw in the Portlet Services component of Oracle WebCenter Portal. The vulnerability is remotely exploitable without authentication via HTTP and requires specific attack preconditions (reflected in the CVSS High AC rating). Successful exploitation allows an attacker to achieve complete system compromise including confidentiality, integrity, and availability impacts. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Patch availability status is pending Oracle's official security advisory publication.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats